OTHER

LightSpy Spyware Linked to China Targets Victims Across 13 Countries, Including the U.S.

Cybersecurity experts have uncovered evidence indicating that spyware associated with China has expanded operations beyond its borders, targeting victims across various countries, including many in Europe and the United States. This already-recognized spyware has acquired new functionalities, allowing it to siphon off extensive data and remotely disable devices.

Research from cybersecurity firm Arctic Wolf reveals that LightSpy, first identified in 2018 and previously linked to Chinese state-sponsored attackers, has transformed into a commercial spyware platform managed by a singular threat actor catering to governments, businesses, and military entities.

The platform is said to feature custom branding, billing, and promotional demonstrations aimed at enticing potential clients.

These revelations underscore the continuing spread of spyware beyond just governmental and state-sponsored players, now reaching into the private sector.

LightSpy operates as a modular spyware system, enabling its operator to target a diverse array of devices, including smartphones, Apple products, Linux servers, and Windows PCs. By leveraging vulnerabilities specific to each device, the spyware can gather considerable amounts of sensitive information, including exact location data, chat logs, screen captures, and saved passwords. Researchers have also indicated that the code is capable of remotely erasing and destroying data on an infected device.

Additionally, researchers found that LightSpy has begun to compromise routers—an alarming development previously unobserved. By taking control of routers, attackers can gain insight into and access other devices connected to the same network.

Some affected routers have been linked to NATO member countries, according to Arctic Wolf.

The firm notes that LightSpy functions via a network of at least 117 servers distributed across various countries worldwide.

The researchers managed to trace this recent activity back to a Chinese contractor when one of the spyware operators misused the LightSpy admin panel to place an order at Kentucky Fried Chicken, inadvertently disclosing his real name and office address.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.